Migrate on-prem managed-threat defense device (FTD) to Cloud-Delivered Firewall Management Center.
This chapter provides the steps to migrate On-Prem Firewall Management Center-managed Threat Defense to Cloud-Delivered Firewall Management Center.
Overview of Firewall Threat Defense to Cloud-Delivered Firewall Management Center migration
Learn how to migrate Firewall Threat Defense devices from On-Premises Firewall Management Center to Cloud-Delivered Firewall Management Center while preserving policies, configurations, and settings through Security Cloud Control Firewall Management.
End-to-End Workflow for Migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center
Provides a workflow diagram for migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center.
Event and Analytics Management options during Firewall Threat Defense migration
Manage where Firewall Threat Defense events and analytics are sent during migration by selecting either on-premises Firewall Management Center or Security Cloud Control as the analytics manager, with options and requirements varying by device model and analytics destination.
Supported features
Learn how Security Cloud Control imports shared policies and device configurations from On-Premises Firewall Management Center, including supported policy types and duplicate policy or object name handling.
Unsupported features
Learn which Firewall Threat Defense migration features are unsupported in Security Cloud Control, including excluded configurations, analytics-only devices, EVE exception rules, rule recommendations, and custom network analysis policy requirements.
Migration guidelines and limitations for VPN configuration
Learn VPN migration guidelines for Firewall Threat Defense devices, including Remote Access VPN and Site-to-Site VPN settings, unsupported items, object overrides, certificates, local users, topology peers, and SASE tunnel limits.
Supported On-Premises Firewall Management Center and Firewall Threat Defense software versions for migration
Find supported On-Premises Firewall Management Center and Firewall Threat Defense versions for migration, including high availability, cluster, multi-instance, interim upgrade, evaluation period, and post-migration requirements.
Prerequisites for Migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center
Find prerequisites for migrating Firewall Threat Defense devices to Cloud-Delivered Firewall Management Center, including DNS, port access, on-premises Firewall Management Center onboarding, user permissions, backups, synchronization, VPN peers, object conflicts, FlexConfig objects, and HA failover health.
Migrate Firewall Threat Defense to Cloud-Delivered Firewall Management Center
Learn how to migrate Firewall Threat Defense devices from On-Premises Firewall Management Center to Cloud-Delivered Firewall Management Center, including device selection, VPN peer handling, commit actions, policy review, deployment options, and migration progress tracking.
View a Firewall Threat Defense Migration Job
Learn how to view Firewall Threat Defense migration job status in Security Cloud Control, review device progress, handle evaluation-period actions, download reports, commit or cancel changes, and address deployment or identity policy issues.
Enable Notification Settings
Learn how to enable email notifications for Firewall Threat Defense migration events in Security Cloud Control, including migration start, failure, success, and pending commit states.
Verify Firewall Threat Defense Connectivity with Cloud-Delivered Firewall Management Center
Learn how to verify Firewall Threat Defense connectivity to Cloud-Delivered Firewall Management Center by checking internet reachability, validating hostname resolution, and correcting DNS configuration from the device CLI.
Use the Troubleshoot Feature for Failed Migrations
Provides a summary and detailed progress of migration steps to help identify and resolve issues on the migration jobs page.